Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
229 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.64% | — | Stivasoft Phpjabbers Newsletter Script | 30/12/2017 | 17/6/2026 | PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel. | |
| Modificada | Media (4) | 0.39% | — | Cisco Jabber | 30/11/2017 | 17/6/2026 | A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to access sensitive communications made by the Jabber client. An attacker could exploit this vulnerability to gain information to conduct additional attacks. The vulnerability is due to the way Cisco Jabber for Windows handles… | |
| Modificada | Media (5.4) | 0.64% | — | Cisco Jabber | 30/11/2017 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Jabber | 30/11/2017 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient… | |
| Modificada | Media (5.5) | 0.36% | — | Cisco JabberCisco Webex Meeting Center | 19/10/2017 | 17/6/2026 | A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input and validation checks in the affected software.… | |
| Modificada | Media (5.5) | 0.36% | — | Cisco Jabber | 19/10/2017 | 17/6/2026 | A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to retrieve user profile information, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input- and validation-checking mechanisms in the system. An… | |
| Modificada | Media (6.1) | 1.0% | — | Phpjabbers Rate ME | 16/10/2017 | 17/6/2026 | rate-me.php in Rate Me 1.0 has XSS via the id field in a rate action. | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Jabber Guest | 7/8/2017 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Jabber Guest Server 10.6(9), 11.0(0), and 11.0(1) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to… | |
| Modificada | Crítica (9.8) | 2.8% | — | Jabberd2 | 4/7/2017 | 17/6/2026 | JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled. | |
| Modificada | Media (6.5) | 1.4% | — | Cisco Jabber Guest | 26/12/2016 | 17/6/2026 | A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts. More Information: CSCvc31635. Known Affected Releases: 10.6(9). Known Fixed Releases: 11.0(0). | |
| Modificada | Alta (7.5) | 8.3% | — | Cisco IOS XECisco Webex Meeting CenterCisco DX Series IP Phones FirmwareCisco IP Phone 7800 Series Firmware+10 | 21/4/2016 | 17/6/2026 | The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686. | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Jabber Guest | 6/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Jabber Guest Server 10.6(8) allows remote attackers to inject arbitrary web script or HTML via the host tag parameter, aka Bug ID CSCuy08224. | |
| Modificada | Media (5.9) | 1.3% | — | Cisco Jabber | 26/12/2015 | 17/6/2026 | Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419. | |
| Modificada | Media (6.5) | 1.9% | — | Jabberd2 | 12/8/2015 | 17/6/2026 | c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via a crafted JID. | |
| Modificada | Media (5) | 2.6% | — | Cisco Jabber | 24/6/2015 | 17/6/2026 | The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Phpjabbers Event Booking Calendar | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Phpjabbers Event Booking Calendar | 13/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and password of the administrator via an update action to the AdminOptions controller or conduct cross-site… | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Phpjabbers Appointment Scheduler | 13/1/2015 | 17/6/2026 | Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Phpjabbers Appointment Scheduler | 13/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices… | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Jabber Guest | 23/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Guest Server in Cisco Jabber allows remote attackers to inject arbitrary web script or HTML via a (1) GET or (2) POST parameter, aka Bug ID CSCus08074. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Jabber Guest | 23/12/2014 | 17/6/2026 | The API in the Guest Server in Cisco Jabber, when HTML5 is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST response, aka Bug ID CSCus19801. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Jabber Guest | 23/12/2014 | 17/6/2026 | The API in the Guest Server in Cisco Jabber, when the HTML5 CORS feature is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST request, aka Bug ID CSCus19789. | |
| Modificada | Media (5) | 1.3% | — | Process-one Ejabberd | 25/10/2014 | 17/6/2026 | ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption. | |
| Modificada | Media (4.3) | 5.5% | — | Cisco Jabber | 16/1/2014 | 17/6/2026 | Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka Bug ID CSCug48056. | |
| Modificada | Media (4.3) | 1.6% | — | Process-one Ejabberd | 17/10/2013 | 17/6/2026 | The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sensitive information via a brute-force attack. |